Authentication
IntraPod uses authenticated sessions and server-resolved identity boundaries when authentication is enabled.
Security and trust
IntraPod is designed around explicit identity, tenant isolation, data minimization, and controlled AI behavior.
IntraPod uses authenticated sessions and server-resolved identity boundaries when authentication is enabled.
Authenticated business data is scoped to the active organization on the server; browser-supplied tenant context is not authoritative.
Sensitive operations require established organization roles in addition to an authenticated session.
Connector credentials are encrypted with authenticated context and are excluded from browser responses and application logs.
Unsafe authenticated browser operations require an exact allowed Origin and the current session CSRF token.
The Support Assistant is grounded in approved documentation, receives no tenant business records, and is protected by bounded, fail-closed usage controls when enabled.
Readiness
Security controls and architecture can contribute to future audit readiness. IntraPod does not claim SOC 2 certification. Any future certification statement will require current, independently supported evidence.
Contact IntraPod